StudyToCert

All certifications / A+ Core 2 / Cheat sheet

A+ Core 2 220-1202 cheat sheet

Every exam tip and key term from the free A+ Core 2 lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Operating systems (28%)

Exam tips

Key terms

Operating system (OS)
The software that manages hardware resources and provides services to applications and users.
Distribution (distro)
A packaged version of Linux that combines the Linux kernel with tools, a package manager and default software.
ChromeOS
Google's lightweight, browser-centred operating system for Chromebooks that updates itself automatically.
Over-the-air (OTA) update
An operating system update delivered wirelessly to a mobile device.
Life cycle
The vendor's published timeline of support phases for a product, from release to retirement.
End-of-life (EOL)
The point after which a vendor stops providing patches and support for a product.
Extended support
A later support phase, sometimes paid, in which only security fixes are provided.
File system
The structure an operating system uses to name, store, locate and protect files on a volume.
NTFS
The Windows default file system, with permissions, EFS encryption, compression, quotas and journaling.
ReFS
Microsoft's Resilient File System, which uses checksums and self-repair for large, integrity-focused storage.
FAT32
A widely compatible legacy file system with a 4 GB maximum file size and no permissions.
exFAT
A flash-oriented file system without FAT32's 4 GB file limit, readable and writable by Windows and macOS.
ext4 and XFS
Journaled Linux file systems; ext4 is a common default and XFS is the Red Hat default for high performance.
APFS
Apple File System, the SSD-optimized default for macOS, iOS and iPadOS with snapshots and encryption.
Journaling
Recording pending changes in a log so a file system can recover consistently after a crash.
ISO file
A single-file image of an optical disc that can be mounted, burned or written to USB.
PXE
Preboot Execution Environment, which lets a network card boot a computer from a deployment server.
Clean install
Installing a fresh OS on a wiped partition, removing previous apps, settings and data.
In-place upgrade
Installing a newer OS version over the existing one while keeping files, settings and most apps.
Image deployment
Copying a standardized, pre-built OS image to many computers.
Repair install
Reinstalling the same OS version over itself to fix system files while keeping data and apps.
MBR
Legacy partition style limited to about 2 TB disks and four primary partitions.
GPT
Modern partition style used with UEFI that supports very large disks and many partitions.
Windows Home
The consumer edition, without domain join, Group Policy Editor, BitLocker management or Remote Desktop host.
Windows Pro
The business edition that adds domain join, Group Policy, BitLocker, Remote Desktop host and Hyper-V.
Windows Enterprise
The volume-licensed edition for organizations with Pro features plus advanced security and management.
Windows Education
Enterprise-level features licensed for schools and universities.
Domain join
Adding a computer to a directory such as Active Directory so it uses central accounts and policies.
Remote Desktop host
A computer that accepts incoming Remote Desktop connections, available in Pro and higher.
TPM 2.0
A hardware security chip that stores keys, required by Windows 11 and used by BitLocker.
Task Manager
Real-time view of processes, performance, startup apps, services and users, opened with Ctrl+Shift+Esc.
Microsoft Management Console (MMC)
A framework that hosts administrative snap-ins such as Event Viewer and Device Manager.
Event Viewer
The snap-in that displays Application, Security and System logs for troubleshooting past events.
Performance Monitor
A tool that logs performance counters over time to build baselines and find trends.
Resource Monitor
A detailed view of which processes are using specific files, disk, network and memory resources.
System Configuration (msconfig)
A tool for changing boot options such as Safe Mode and disabling services for clean-boot troubleshooting.
Registry
The hierarchical database of Windows and application settings, edited with regedit.
robocopy
Robust File Copy, a resilient copy tool that retries, resumes, preserves permissions and can mirror folders.
diskpart
An interactive command-line tool for managing disks, partitions and volumes with no undo.
chkdsk
Checks a volume for file system errors; /f fixes errors and /r also finds bad sectors.
sfc
System File Checker, which scans and repairs protected Windows system files.
DISM
Deployment Image Servicing and Management, which repairs the Windows component store that sfc relies on.
gpupdate and gpresult
gpupdate applies Group Policy now; gpresult reports which policies were applied.
nslookup
A tool that queries DNS servers to test name resolution.
pathping
Combines ping and tracert to measure latency and packet loss at each hop over time.
Settings app
The modern Windows configuration interface, opened with Windows key + I.
Control Panel
The classic Windows configuration interface containing applets such as Programs and Features and Power Options.
Sleep
A low-power state that keeps the session in RAM for very fast resume but still uses power.
Hibernate
Saves RAM contents to hiberfil.sys on disk and powers off fully, resuming more slowly with no power used.
Fast startup
A shutdown mode that hibernates the kernel session to speed the next boot; Restart bypasses it.
Default apps
Settings that decide which application opens each file type or link type.
Active hours
The period when Windows Update avoids automatically restarting the device.
Workgroup
A peer-to-peer arrangement where each Windows computer keeps its own local accounts.
Domain
A centrally managed network where a domain controller provides accounts, authentication and Group Policy.
UNC path
A network path in the form \\server\share used to reach shared resources.
Mapped drive
A drive letter assigned to a network share so it appears like a local drive.
APIPA
Automatic Private IP Addressing, which assigns a 169.254.x.x address when no DHCP server responds.
Network profile
The Public, Private or Domain category that sets discovery, sharing and firewall behaviour for a connection.
Proxy server
A server that forwards web requests on a client's behalf for filtering, logging or caching.
Metered connection
A setting that tells Windows data is limited or costly so it reduces background downloads.
.dmg
A macOS disk image file that mounts like a drive and usually contains an app to drag into Applications.
.pkg
A macOS installer package that runs a wizard and can install components in several system locations.
Time Machine
The built-in macOS backup tool that keeps hourly, daily and weekly versions on an external or network drive.
FileVault
macOS full-disk encryption, protected by the user's password and a recovery key.
Keychain
The macOS password manager that stores passwords, certificates and secure notes.
Spotlight
The macOS system-wide search, opened with Command + Space.
Disk Utility
The macOS tool for erasing, formatting, partitioning and repairing drives with First Aid.
Force Quit
Ends an unresponsive macOS app, opened with Command + Option + Esc.
chmod
Changes file permissions using symbolic notation or octal numbers such as 750.
chown
Changes the owner and group of a file or directory.
sudo
Runs a single command with elevated privileges using the user's own password, with logging.
su
Switches to another user account, root by default, using that account's password.
Package manager
A tool such as apt or dnf that installs and updates software from repositories and resolves dependencies.
/etc/shadow
The root-only file that stores hashed passwords and password-aging information.
/etc/fstab
The file listing file systems to mount automatically at boot.
/etc/resolv.conf
The file listing the DNS servers a Linux system uses.
32-bit (x86)
An architecture whose applications can address about 4 GB of memory; runs on 32-bit and most 64-bit systems.
64-bit (x64)
An architecture that can address far more memory and requires a 64-bit operating system.
System requirements
The vendor's minimum and recommended OS, CPU, RAM, GPU and storage needed to run software.
VRAM
Video RAM on a graphics card, required in minimum amounts by graphics-heavy applications.
Hash verification
Comparing a downloaded file's hash with the vendor's published value to confirm it is unaltered.
Business impact
The effect of an installation on devices, the network, operations and licensing or compliance.
Cloud productivity suite
A subscription service providing hosted email, storage, office apps and collaboration tools.
IMAP
Internet Message Access Protocol, which keeps mail on the server and syncs folders across devices.
POP3
Post Office Protocol version 3, which downloads mail to a single device and usually removes it from the server.
SMTP
Simple Mail Transfer Protocol, used to send email.
Synced storage
A cloud service that keeps files synchronized across a user's devices, such as OneDrive or Google Drive.
Files-on-demand
A sync feature that lists all files but downloads content only when the file is opened.
Licence assignment
Allocating a subscription plan to a user so they receive the included apps and services.
Deprovisioning
Disabling a departing user's access, handling their data per policy and reclaiming their licence.

Domain 2: Security (28%)

Exam tips

Key terms

Defense in depth
Using several layers of security controls so that one failure does not expose everything.
Access control vestibule
A two-door entry space that allows only one door open at a time, preventing tailgating.
Badge reader
A device that reads an ID card or fob, unlocks for authorized users and logs entries.
Bollard
A short, sturdy post that blocks vehicles while allowing pedestrians to pass.
Video surveillance
Cameras that deter, monitor and record activity for evidence.
Alarm system
Sensors such as door contacts, glass-break and motion detectors that alert when triggered.
Tailgating
Following an authorized person through a secured entrance without authenticating.
Least privilege
Granting users and services only the minimum access required for their tasks.
Zero trust
A model where no user or device is trusted by default and every access request is verified.
Multifactor authentication (MFA)
Authentication using two or more different factor types: know, have and are.
Single sign-on (SSO)
Authenticating once to an identity provider to access many applications.
Directory service
A central database of users, groups and computers, such as Active Directory, used for authentication.
Access control list (ACL)
A list of permissions or rules stating who or what traffic is allowed or denied.
Mobile device management (MDM)
Central enrolment and control of devices to enforce policy and remotely lock or wipe them.
Data loss prevention (DLP)
Tools that detect and block sensitive data from leaving the organization improperly.
Microsoft Defender Antivirus
Built-in Windows anti-malware with real-time, cloud-delivered and scheduled scanning.
User Account Control (UAC)
A feature that runs users with standard rights and prompts before elevating for system changes.
Share permissions
Full Control, Change and Read permissions that apply only to network access to a shared folder.
NTFS permissions
File and folder permissions that apply both locally and over the network.
Inheritance
Child files and folders automatically receiving the permissions of their parent folder.
BitLocker
Full-volume encryption for Windows, usually protected by the TPM and a recovery key.
EFS
Encrypting File System, which encrypts individual NTFS files tied to a user's certificate.
Windows Hello
Device-bound sign-in using a PIN, fingerprint or facial recognition.
WPA2
Wi-Fi security standard using AES-CCMP, in Personal (pre-shared key) or Enterprise (802.1X) modes.
WPA3
The current Wi-Fi security standard, using SAE in Personal mode and requiring Protected Management Frames.
AES
Advanced Encryption Standard, the strong cipher used by WPA2 and WPA3.
TKIP
Temporal Key Integrity Protocol, a deprecated cipher from the original WPA.
RADIUS
An open AAA protocol over UDP, commonly used for Wi-Fi, VPN and network access authentication.
TACACS+
A Cisco-originated AAA protocol over TCP that encrypts the whole payload, used for device administration.
Kerberos
The ticket-based authentication protocol used in Active Directory domains for single sign-on.
802.1X
Port-based network access control that passes authentication to a server such as RADIUS.
Virus
Malware that attaches to a host file or program and spreads when that host is run or shared.
Trojan
Malware disguised as legitimate software that carries a hidden malicious function.
Rootkit
Malware that hides deep in the OS or firmware to conceal itself and keep privileged access.
Ransomware
Malware that encrypts or steals data and demands payment.
Fileless malware
Malware that runs in memory and abuses built-in tools instead of installing executable files.
Cryptominer
Malware that uses a victim's CPU or GPU to mine cryptocurrency.
EDR
Endpoint detection and response, which records endpoint activity, detects threats and can isolate devices.
Email security gateway
A filter that blocks spam, phishing and malicious attachments before they reach mailboxes.
Phishing
Fraudulent messages impersonating trusted senders to steal credentials or deliver malware.
Whaling
Phishing aimed at senior executives.
Vishing and smishing
Social engineering by voice call and by SMS text message respectively.
Business email compromise (BEC)
Using a compromised or spoofed business email account to trick staff into payments or data release.
Evil twin
A rogue access point imitating a legitimate Wi-Fi network to intercept traffic.
On-path attack
An attacker positioned between two parties to intercept or alter communication.
Zero-day
A vulnerability with no available patch because the vendor has had no time to fix it.
Supply chain attack
Compromising a trusted supplier or its products to reach that supplier's customers.
Investigate and verify
Step 1: confirm symptoms are caused by malware before taking action.
Quarantine
Step 2: isolate the infected system from networks and shared media to stop spread.
System Restore
A Windows feature that saves restore points, which can harbour malware and so is disabled during cleanup.
Remediation
Step 4: update anti-malware, then scan and remove using Safe Mode or a preinstallation environment, or reimage.
Preinstallation environment
A minimal boot environment such as Windows PE used to scan while the infected OS is not running.
Restore point
A snapshot of system files and settings that Windows can roll back to.
End-user education
Step 7: teaching the user how the infection happened and how to avoid it.
Hardening
Reducing a system's attack surface by removing, disabling and securing features.
Data-at-rest encryption
Encrypting stored data, for example with BitLocker or FileVault, so a stolen drive is unreadable.
Password policy
Rules for password length, complexity, history, expiration and lockout, often enforced by Group Policy.
Account lockout
Temporarily disabling an account after a set number of failed sign-in attempts.
Screen lock timeout
Automatically locking the session after a period of inactivity, requiring a password to resume.
AutoRun and AutoPlay
Features that launch or prompt actions when media is inserted; hardening disables them.
Guest account
A built-in account allowing access without personal credentials, which should remain disabled.
Screen lock
A PIN, passcode, pattern or biometric required to unlock a mobile device.
Remote wipe
Erasing a device's data remotely, which must be configured before loss.
Locator app
A service that shows a lost device's location and can lock it or play a sound.
Device encryption
Encryption of mobile storage tied to the screen lock to protect data at rest.
BYOD
Bring your own device, where employees use personal devices for work, usually with a separate work profile.
Selective wipe
Removing only corporate apps and data from a device while leaving personal data intact.
COPE
Corporate-owned, personally enabled devices that the company owns but allows some personal use.
Shredding
Mechanically cutting media into small pieces so it cannot be read or reassembled.
Degaussing
Using a strong magnetic field to erase magnetic media; ineffective on SSDs, flash and optical discs.
Drilling
Boring holes through drive platters to make a drive unusable, less thorough than shredding.
Incineration
Burning media completely, often for paper and highly sensitive material.
Wiping
Overwriting all addressable storage so previous data cannot be recovered, allowing reuse.
Standard format
Creating a new empty file system without removing old data, which remains recoverable.
Secure erase
A drive's built-in command, important for SSDs, that sanitizes all cells including those hidden by wear leveling.
Certificate of destruction
A vendor's document recording which devices were destroyed, how and when.
SOHO router
An all-in-one device combining routing, switching, wireless access, firewall and DHCP for a small office or home.
WPS (Wi-Fi Protected Setup)
A convenience feature for joining Wi-Fi by button or PIN whose PIN method can be guessed quickly, so it should be disabled.
UPnP (Universal Plug and Play)
A feature that lets devices open router ports automatically without approval, which malware can abuse.
Port forwarding
A rule that sends traffic arriving on an external port to a specific internal IP address and port.
DHCP reservation
A setting that always gives the same IP address to a device identified by its MAC address.
Content filtering
Blocking websites by category or domain at the router or another filtering device.
Guest network
A separate SSID and network segment that gives visitors internet access without reaching internal resources.
Screened subnet
A separate network zone, formerly called a DMZ, for devices that must be reachable from the internet.
Hash check
Comparing a computed hash of a downloaded file with the vendor's published value to confirm the file was not altered.
Browser extension
An add-on that extends browser features and may be able to read and change the pages you visit.
Password manager
A tool that generates, stores and auto-fills unique strong passwords and will not fill them on look-alike domains.
Certificate authority (CA)
A trusted organization that issues digital certificates binding a public key to a domain name.
Pop-up blocker
A browser feature that stops sites from opening unwanted new windows, with exceptions for trusted sites.
Private browsing
A mode that does not keep history, cookies or form data after the window closes, without hiding activity from networks or sites.
Profile sync
Signing the browser into an account so bookmarks, passwords, extensions and settings follow the user across devices.

Domain 3: Software troubleshooting (23%)

Exam tips

Key terms

BSOD (stop error)
A Windows fatal error screen that halts the system and shows a stop code, often caused by drivers, RAM or heat.
Stop code
The identifier on a blue screen that names the kind of fatal error and helps locate the cause.
Memory leak
A program fault where memory is allocated but never released, gradually exhausting RAM.
No OS found
A boot error meaning firmware could not find a bootable operating system on the devices in the boot order.
USB controller resource warning
A message that a USB controller has run out of endpoints or bandwidth because too many devices share it.
Time drift
A system clock that is wrong or gradually wanders, which can break Kerberos authentication and certificate checks.
CMOS battery
The small motherboard battery that keeps firmware settings and the real-time clock while the PC is unplugged.
sfc /scannow
The System File Checker command that scans and repairs protected Windows system files from the component store.
DISM
Deployment Image Servicing and Management, used with /RestoreHealth to repair the component store that sfc depends on.
System Restore
A feature that returns system files, drivers, registry and programs to an earlier restore point without changing personal files.
In-place repair install
Running Windows setup over the existing installation to replace system files while keeping apps and data.
Reimage
Wiping a computer and reinstalling a standard operating system image, the most thorough and disruptive fix.
Rebuilding a user profile
Replacing a corrupt Windows user profile with a fresh one and copying the user's data back.
Roll back
Reverting a driver or update to the previous version when the new one causes problems.
Event Viewer
The Windows log reader showing Application, System, Security and other logs with levels, sources and Event IDs.
Event ID
A number that identifies a specific type of logged event and can be looked up in documentation.
Reliability Monitor
A timeline of failures, warnings and installs used to find what changed before a problem began.
Task Manager
A tool showing current processes, performance, startup apps and services.
Resource Monitor
A detailed view of per-process CPU, memory, disk and network activity, opened from Task Manager.
Safe Mode
A startup mode that loads only essential drivers and services to isolate third-party causes.
Windows Recovery Environment (WinRE)
A recovery OS offering Startup Repair, Safe Mode access, System Restore, uninstalling updates and a command prompt.
Force stop
Ending an app's process completely so it can be relaunched from a clean state.
Clear cache
Removing an app's temporary files without deleting the user's account or settings.
Clear data
Resetting an app to its freshly installed state, removing its settings and sign-in.
Offload app
An iOS option that removes an app but keeps its documents and data for reinstallation.
Reset network settings
Clearing saved Wi-Fi networks, Bluetooth pairings and VPN settings to fix stubborn connectivity problems.
NFC (near-field communication)
Very short-range wireless used for contactless payments and tap-to-pair.
Rotation lock
A setting that keeps the screen in portrait orientation regardless of how the device is held.
Accelerometer
A sensor that detects movement and orientation, used for autorotation.
Sideloading
Installing an app from outside the official app store, bypassing its security screening.
APK (Android Package)
The file format used to distribute and install Android apps.
Jailbreaking
Removing Apple's iOS restrictions to gain full control, which weakens the security model.
Rooting
Gaining full administrative (root) access on Android, which removes built-in protections.
Unofficial app store
A third-party marketplace that does not screen apps as thoroughly as official stores.
Scareware
Fake security warnings designed to frighten users into installing malware, paying or calling a scammer.
Stalkerware
Hidden monitoring software installed to track a person's location, messages or activity without consent.
Rogue antivirus
Fake security software that reports invented infections to extort payment or install malware.
Hosts file
A local file that maps names to IP addresses before DNS is used, which malware can edit to redirect or block sites.
Rogue proxy
An unauthorized proxy setting that routes the PC's web traffic through a server controlled by an attacker.
System File Checker (sfc)
A Windows tool that scans protected system files and repairs altered or missing ones.
Quarantine
Isolating an infected system from the network so malware cannot spread or communicate.
Malware removal procedure
CompTIA's seven ordered steps from verifying symptoms through educating the user.
Adware
Unwanted software that displays advertising, often through pop-ups, injected ads or redirected searches.
Browser hijacker
Software or an extension that changes the home page, search engine or new tab page without consent.
Certificate warning
A browser message that a site's certificate is expired, mismatched or from an untrusted issuer.
On-path attack
An attack where someone intercepts traffic between two parties, formerly called man-in-the-middle.
Rogue root certificate
An unauthorized certificate authority certificate installed so that intercepted traffic appears trusted.
Cryptomining script
Code that uses the visitor's CPU to mine cryptocurrency, slowing the browser.
Tech support scam
A fake alert urging the user to call a number or allow remote access to fix a non-existent problem.
Persistence
A mechanism that lets malware survive reboots or removal attempts, such as a scheduled task or startup entry.
Run key
A registry location whose entries launch programs automatically when a user signs in.
Startup folder
A folder, opened with shell:startup, whose shortcuts run at sign-in.
Task Scheduler
The Windows tool that runs programs on triggers such as logon, startup or a timer.
Autoruns
A Sysinternals tool that lists every autostart location on a Windows system in one view.
Proxy setting
A configuration that routes web traffic through an intermediate server, which malware may set to intercept traffic.
netsh winhttp show proxy
A command that displays the system-wide proxy used by Windows services.

Domain 4: Operational procedures (21%)

Exam tips

Key terms

Ticketing system
Software that records, routes and tracks support requests and incidents from report to resolution.
Category
A classification of a ticket by type, such as hardware or network, used for routing and reporting.
Severity
A measure of how serious a problem's impact is on users and the business.
Priority
The order in which tickets are handled, usually set from impact and urgency.
Escalation
Passing a ticket to a higher tier or specialist when it exceeds the current technician's skill, authority or time limit.
Progress notes
Time-ordered records of actions, findings and communications on a ticket.
Resolution
The closing note stating the cause, the fix applied and the user's confirmation.
Inventory list
A record of every asset with details such as ID, model, serial number, location, status and assigned user.
CMDB (configuration management database)
A database of configuration items and the relationships and dependencies between them.
Configuration item (CI)
Any component tracked in a CMDB, such as a server, application, service or document.
Asset tag
A label with a unique organizational ID, often a barcode, QR code or RFID tag, attached to equipment.
Procurement life cycle
The stages of an asset from purchase request through deployment, maintenance and disposal.
Software license compliance
Ensuring the number and type of installations match what the license agreements allow.
Assigned user
The person recorded as responsible for a specific asset.
Acceptable use policy (AUP)
A policy stating what users may and may not do with an organization's systems and data.
Incident report
A factual record of an incident: what happened, when, what was affected and what actions were taken.
Standard operating procedure (SOP)
Step-by-step instructions for performing a routine task consistently.
Onboarding checklist
A list of steps for setting up a new user's accounts, access, equipment and training.
Offboarding checklist
A list of steps for removing a departing user's access, recovering equipment and handling their data.
Service level agreement (SLA)
A formal agreement defining service targets such as response times and availability.
Knowledge base (KB) article
A documented solution or how-to guide for technicians or end users.
Change request
A form describing a proposed change, its purpose, scope, schedule, owner and risk.
Scope
The systems, users, locations and services a change will affect.
Risk analysis
An assessment of the likelihood and impact of a change failing, and of not making it.
Change advisory board (CAB)
A group of stakeholders that reviews and approves or rejects normal changes.
Sandbox
An isolated test environment that mirrors production so changes can be tested safely.
Rollback plan
Documented steps to return a system to its previous state if a change fails.
End-user acceptance
Confirmation by users or the business owner that the changed system meets their needs.
Full backup
A copy of all selected data, simplest to restore but the slowest and largest to create.
Incremental backup
A copy of data changed since the last backup of any type; restore needs the full plus every incremental.
Differential backup
A copy of data changed since the last full backup; restore needs the full plus the latest differential.
Synthetic full backup
A full backup assembled on backup storage from a previous full and later incrementals.
3-2-1 rule
Keep three copies of data on two types of media with one copy off-site.
Grandfather-father-son (GFS)
A rotation scheme using daily, weekly and monthly backup sets kept for increasing lengths of time.
RPO and RTO
Recovery point objective is the acceptable data loss; recovery time objective is how quickly service must return.
ESD (electrostatic discharge)
A sudden flow of static electricity that can damage electronic components without being felt.
ESD wrist strap
A strap with a resistor that connects you to ground so static bleeds away safely while working on components.
ESD mat
A grounded work surface that keeps components and tools at the same potential.
Antistatic bag
Packaging that shields components from static charges during storage and transport.
Grounding
Connecting equipment to earth so fault current flows to ground instead of through a person.
Class C fire
A fire involving energized electrical equipment, fought with non-conductive agents such as CO2.
PPE (personal protective equipment)
Gear such as safety glasses, gloves and masks that protects the wearer from hazards.
Safety data sheet (SDS)
A manufacturer's document describing a product's hazards, safe handling, first aid, spill response and disposal.
E-waste
Discarded electronic equipment that must be recycled through certified channels because it contains hazardous materials.
Toner vacuum
A vacuum with fine filtering designed to safely collect toner particles.
Surge suppressor
A device that diverts voltage spikes away from connected equipment, rated in joules.
UPS (uninterruptible power supply)
A battery-backed device that keeps equipment powered through outages and sags long enough for a clean shutdown.
Brownout (sag)
A temporary drop in voltage below normal levels.
Hot aisle / cold aisle
A server room layout where equipment intakes face a cool aisle and exhausts face a hot aisle.
Chain of custody
A documented record of everyone who handled evidence, when and what they did, preserving its integrity.
EULA (end-user license agreement)
The contract defining the terms under which software may be used.
DRM (digital rights management)
Technology that restricts copying and use of digital content to enforce licensing.
Open-source license
A license that makes source code available and permits use, modification and sharing under stated conditions.
PII (personally identifiable information)
Any data that can identify a specific person.
PHI (protected health information)
Health information linked to an individual, protected in the US under HIPAA.
PCI DSS
The Payment Card Industry Data Security Standard for protecting payment card data.
GDPR
The EU General Data Protection Regulation governing personal data of people in the EU.
Active listening
Giving full attention, not interrupting, taking notes and restating the problem to confirm understanding.
Open-ended question
A question that invites a detailed answer, used to gather information.
Closed-ended question
A question with a short or yes/no answer, used to narrow down a problem.
Jargon
Technical terms and acronyms that a non-technical customer may not understand.
Confidentiality
Protecting customers' private information and not reading, copying or discussing it.
Setting expectations
Telling the customer what will be done, how long it will take and what options and costs exist.
Follow-up
Contacting the customer after the work to confirm the problem stays solved.
Script
A plain-text file of commands executed in order by an interpreter.
Batch file (.bat)
A Windows script run by the Command Prompt interpreter.
PowerShell (.ps1)
Microsoft's powerful scripting language and shell for administering Windows and other systems.
Shell script (.sh)
A script for Linux or macOS run by bash or another shell.
Variable
A named storage location that holds a value a script can use and change.
Loop
A structure that repeats a set of commands, for example for each item in a list.
Execution policy
A PowerShell setting that controls whether and which scripts are allowed to run.
RDP (Remote Desktop Protocol)
Microsoft's protocol for full graphical remote desktop sessions, by default on TCP port 3389.
SSH (Secure Shell)
An encrypted remote command-line protocol, by default on TCP port 22, that replaced Telnet.
VNC (Virtual Network Computing)
A cross-platform screen-sharing protocol that controls the console session, often needing an encrypted tunnel.
VPN (virtual private network)
An encrypted tunnel connecting a remote device to a private network.
RMM (remote monitoring and management)
A platform for monitoring, patching, scripting and remotely controlling many endpoints.
WinRM (Windows Remote Management)
A service that lets administrators run PowerShell commands on remote Windows computers.
SPICE
A remote display protocol used to access virtual machine consoles.
NLA (Network Level Authentication)
An RDP setting that requires users to authenticate before a remote session is created.
Generative AI
AI that creates new text, images or code based on patterns learned from training data.
Large language model (LLM)
An AI model trained on large amounts of text to generate and interpret language.
Hallucination
A confident but false or invented output produced by an AI model.
Bias
Systematic unfairness in AI output caused by skewed training data or design.
Appropriate-use policy
An organizational policy defining approved AI tools, permitted data and review requirements.
Public model
A consumer AI service open to anyone whose terms may allow storing or training on user input.
Private model
An AI model run by or contracted for an organization that keeps its data under the organization's control.
Study A+ Core 2 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the A+ Core 2 study plan